Why MSPs Should Stop Selling Phishing Simulations and Start Selling Behavior Change

Why MSPs Should Stop Selling “Phishing Simulations” and Start Selling “Behavior Change”
The MSP security awareness training category has spent years training the market to think about phishing simulations as the product. That framing made sense when phishing simulations were a novel capability.
In 2026, they’re a commodity — and selling a commodity is the slowest possible path to MSP margin.
The MSPs winning consistently in 2026 have made a subtle but important pivot: they sell behavior change, not phishing simulations. This guide explains why the framing matters, how to make the switch, and what it does to your sales conversations.
The problem with selling “phishing simulations”
When the MSP positions phishing simulations as the product, three things happen:
1. The conversation becomes about features
Template count, attack type coverage, reporting depth. The client compares vendors on feature parity, which means the cheapest vendor with sufficient features wins.
You end up in RFP hell: side‑by‑side grids, nitpicking over minor capabilities, and prospects asking for discounts because “this other platform has 1,000 templates for less.”
2. The program becomes a checkbox
“Phishing simulations” as a product implies a defined deliverable. The client measures whether they got what they paid for:
- Did the simulations run?
- Did we get the reports?
- Did users get their training modules?
If the answer is yes, the box is checked. There’s no narrative about what the program is producing beyond its own execution.
3. Renewal conversations get dangerous
If the product is phishing simulations and the simulations have been running, the client’s renewal question becomes:
“Do we still need this?”
Because there’s no measurable outcome beyond “we ran the thing,” the answer feels arbitrary. Budget pressure turns your line item into an easy target.
Result: MSPs that sell phishing simulations as the product end up in commodity pricing dynamics, defensive renewals, and slow service-line growth.
The behavior-change framing
The MSPs that have moved past this sell behavior change as the product.
- Phishing simulations are a delivery mechanism for behavior change, not the product itself.
- Training is a delivery mechanism for behavior change.
- Reporting demonstrates behavior change.
The whole program is in service of one measurable outcome: employees getting better at recognizing and responding to attacks.
This shift sounds small, but the implications are large.
1. The conversation becomes about outcomes
Instead of talking about templates and features, you talk about:
- Click rate trends
- Report rate trends
- Time-to-recognition trends
The client cares about whether their team is getting better, not whether the platform supports 1,000 templates.
2. The program becomes a managed service
Behavior change is ongoing. It requires:
- Consistent cadence
- Smart adaptation
- Continuous improvement
Those are things an MSP delivers as a managed service, not a tool the client buys and forgets.
3. Renewal conversations become easy
If the product is behavior change and the data shows the team’s behavior improved, the renewal answers itself.
If the team’s behavior didn’t improve, the conversation is about why and what to change — not whether to pause the program.
How to make the framing switch
The switch shows up in three places:
- The sales conversation
- The QBR
- The platform language MSPs use internally
In the sales conversation
Stop opening with the platform. Open with the outcome: "In six months, your team will recognize and report attacks measurably better than they do today, and you’ll see the trend line every month." Phishing simulations, training moments, and reporting come up later, as the mechanisms that produce that trend line. Prospects can compare template counts across vendors; they cannot comparison-shop an outcome you’ve committed to demonstrating.
In the QBR
Lead with two numbers: training completion and the reporting-rate trend. Click rate is context, never the headline — a click on a simulation is a coached learning moment, not a verdict on a person. When the reporting rate is rising, the story writes itself: employee instincts are strengthening, and the client’s team is becoming part of the detection layer. That is a story worth renewing.
In the language your team uses
Words carry framing. A "program" is an ongoing service; a one-off blast is a task. A "simulation" is practice; a "test" implies pass/fail and quietly reintroduces blame. Teams that talk internally about running programs and coaching employees sell behavior change naturally, because that is what they actually operate.
The metric that makes behavior change sellable: SERR
Behavior change needs a number, and click rate is the wrong one. Click rate measures failure — how many people fell for the simulation. It says nothing about whether the security team would have found out about a real attack in time to act.
The number that predicts real-world outcomes is SERR: the Suspicious Email Reporting Rate — how often employees flag the suspicious message instead of ignoring it, or worse, clicking and staying quiet. One trained person reporting a real phish in the first minute protects everyone who received it. That is defense, and it is measurable, month over month.
This is why Hook Security treats SERR as the primary program metric, uses click rate as a diagnostic, and deliberately does not assign per-person risk scores. Scoring individuals rebuilds the blame culture that makes employees hide mistakes; a rising reporting rate is what a healthy security culture looks like in data.
Why behavior change must be continuous (the research)
The strongest argument for selling behavior change as an ongoing managed service is peer-reviewed. A field study of 409 employees found that the effects of security awareness training fade back toward baseline in roughly six months, and recommended reinforcement at least every six months — with video-based and interactive refreshers retaining best (Reinheimer et al., USENIX SOUPS 2020).
Annual compliance training is therefore structurally incapable of producing behavior change — the effect decays long before the next session. A monthly cadence of short training moments and realistic phishing simulations is not a nice-to-have; it is the minimum viable dose. And a monthly cadence across every client is exactly the kind of work that should run on Autopilot rather than on an MSP technician’s calendar.
What the framing does to pricing and renewals
Commodity phishing simulations get priced like a commodity — downward, against the cheapest feature-complete alternative. Behavior change delivered as a managed service is priced against the value of the outcome and the cost of the client operating it themselves.
The economics leave room for both sides. Hook Security’s published MSRP is $2 per seat per month ($20 per seat per year), or $999 per year flat for businesses under 50 seats — and MSP partners resell on partner pricing. An MSP bundling behavior change into a broader security service prices the service, not the seat license, and the monthly trend line in every QBR keeps demonstrating why it is worth it.
That is the whole pivot: same platform, same simulations, same training — but the product you sell is the improvement, and the improvement is the one thing a cheaper competitor cannot undercut without proving it too.
Frequently asked questions
What does it mean to sell behavior change instead of phishing simulations?
It means positioning measurable improvement in employee security behavior as the product, with phishing simulations, training, and reporting as the mechanisms that produce and demonstrate it. The client buys an outcome - a team that recognizes and reports attacks - rather than a tool that sends simulated emails.
What is SERR and why should MSPs lead with it?
SERR is the Suspicious Email Reporting Rate: how often employees report suspicious messages instead of ignoring or clicking them. Click rate measures failure on a simulation; SERR measures whether a real attack would get caught in time to respond. A rising SERR is direct, client-legible evidence of behavior change, which makes it the natural headline metric for QBRs and renewals.
How often does security awareness training need to run to change behavior?
Continuously. Peer-reviewed field research found training effects fade back toward baseline in roughly six months without reinforcement, and that video-based, interactive refreshers work best (Reinheimer et al., USENIX SOUPS 2020). Monthly micro-training plus ongoing phishing simulations is the cadence that sustains behavior change; annual compliance training decays before it can compound.
How should an MSP price a behavior-change program?
Price the managed service and its outcome, not the seat license. For reference, Hook Security publishes its standard MSRP - $2 per seat per month, $20 per seat per year, or $999/year flat for businesses under 50 seats - with reseller pricing for MSP partners. MSPs typically bundle the program into a broader security offering priced on the value of managed, measurable human-risk reduction.
Keep reading
- What is PsySec? - the psychology-first methodology behind behavior change.
- How MSPs put security awareness on Autopilot - running the monthly cadence without adding headcount.
- What done-for-you SAT means in 2026 - five tests for genuinely managed delivery.
- Security awareness training statistics (2026) - the sourced numbers behind the argument, including the decay research.
Ready to Strengthen Your Security Culture?
See how Hook Security can help protect your organization.